Release rh-podman-desktop-1.1.2-1.el10_2 ALSA-2026:57590
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 15/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Active
- Tech stack
- go, javascript
- Domain
- desktop-dev, release, security
Research direction
The issue names no source files or tests. Start by reviewing the affected packages, rh-podman-desktop-1.1.2-1.el10_2.x86_64 and its _v2 variant, along with JIRA AlmaLinux-238929. Done means releasing RH Podman Desktop 1.1.2 to AlmaLinux 10.2 Extensions with the listed security, bug-fix, and enhancement updates.
Written by the indexing model from the issue text.
Description
rh-podman-desktop security, bug fix, and enhancement update
Severity: Important
Description
AlmaLinux build of Podman Desktop is a graphical tool for managing containers using Podman. It allows users to run, manage, and configure containers and container images using a desktop GUI.
Security Fix(es):
- github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
- ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
- protobufjs: protobufjs: Denial of Service via crafted JSON descriptors (CVE-2026-45740)
- ws: ws: Uninitialized memory disclosure via
websocket.close()withTypedArray(CVE-2026-45736) - devalue: devalue: Excessive memory consumption via deserialization of sparse arrays (CVE-2026-42570)
- tmp: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705)
- form-data: form-data: Form field override via CRLF injection (CVE-2026-12143)
- webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration (CVE-2026-9595)
- ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments (CVE-2026-48779)
- extract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass (CVE-2026-56876)
- fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization (CVE-2026-13676)
- brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
- tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
- tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)
- js-yaml: js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869)
- protobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877)
- grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiation (CVE-2026-48068)
- linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801)
- dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978)
- brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
- postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)
- postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153)
- brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152)
- ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192)
Bug Fix(es) and Enhancement(s):
- Release RH Podman Desktop 1.1.2 to AlmaLinux 10.2 Extensions (JIRA:AlmaLinux-238929)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages:
rh-podman-desktop-1.1.2-1.el10_2.x86_64
rh-podman-desktop-1.1.2-1.el10_2.x86_64_v2
- Dominant language
- No language data
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from AlmaLinux/updates
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
-
Difficulty 1/5 Under an hour Newbie friendliness 60/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
Difficulty 1/5 Under an hour Newbie friendliness 20/100
All issues in AlmaLinux/updates
Similar issues
-
area: assistant
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 1 day
-
bug help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
HafidIdrissi/Time-Tracker#317 ·
Maintainers usually reply within 1 day
-
Bug: Minor
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
TouhouGleaners/danmaku-sender#450 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
siyuan-note/siyuan#20165 ·
Maintainers usually reply within 1 day
-
[APP BUG]: Sorting by name after searching can bring up irrelevant resultsPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
shadps4-emu/shadps4-qtlauncher#465 ·
Maintainers usually reply within 1 day